Sap Netweaver Application Server For Abap and Abap Platform
26 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Sap Netweaver Application Server For Abap and Abap Platform, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Sap Netweaver Application Server For Abap and Abap Platform CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 1 |
| 2025-01 | 4 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 2 |
| 2025-08 | 1 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 2 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 26 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High3
- Medium18
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Sap Netweaver Application Server For Abap and Abap Platform.
- CVE-2026-66767Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform7.7
- CVE-2026-40135OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform6.5
- CVE-2025-42883Insecure File Operations vulnerability in SAP NetWeaver Application Server for ABAP (Migration Workbench)2.7
- CVE-2025-42882Missing Authorization check in SAP NetWeaver Application Server for ABAP4.3
- CVE-2025-42918Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing)4.3
- CVE-2025-42935Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Manager)4.1
- CVE-2025-42969Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform6.1
- CVE-2025-42961Missing Authorization check in SAP NetWeaver Application Server for ABAP4.9
- CVE-2025-0070Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform9.9
- CVE-2025-0066Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework)9.9
- CVE-2025-0063SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform8.8
- CVE-2025-0053Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform5.3
- CVE-2024-47585Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform4.3
- CVE-2024-47586NULL Pointer Dereference vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform5.3
- CVE-2024-45285Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform5.4
Product grouping is registry-driven, with AI assist and human review. How it works